Kali365

S9044

Malware.View on attack.mitre.org

About this malware

Kali365 is a Phishing-as-a-Service (PHaaS) kit first observed in April 2026 that generates victim-targeted lures across multiple operating systems to induce users into copying and pasting actor-controlled commands for local execution. Kali365 incorporates on-demand device code generation and mirrors the copy-paste execution tradecraft associated with ClickFix. Operators have used Kali365 to harvest victims' OAuth tokens and session cookies through adversary-in-the-middle (AiTM) interception, enabling account takeover. Kali365 PHaaS was first observed in April 2026. Kali365 has also been affiliated with other branding to include Octopi365 and Freedom365.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1059.007
JavaScript

Kali365 has executed JavaScript within victims' browsers through a React frontend that detects browser sessions to evade automated analysis, auto-copies actor-generated device codes to the victim's clipboard, and polls the actor's C2 infrastructure every three seconds to confirm when OAuth token capture has completed..

T1071.001
Web Protocols

Kali365's desktop client has made Microsoft Graph API calls using the distinct User-Agent string `kali365-live/1.0.0` to access victim mailboxes and enumerate account data following OAuth token capture.

T1087.003
Email Account

Kali365 has leveraged an Exchange Admin module that utilizes Graph to enumerate mailboxes in victim environments.

T1090
Proxy

Kali365 has leveraged Cloudflare workers as reverse proxy infrastructure.

T1102
Web Service

Kali365 has used Cloudflare Workers to redirect traffic and to host malicious phishing pages. Kali365 has also leveraged Telegram chat to facilitate administrative tasks for the panel across affiliate users.

T1185
Browser Session Hijacking

Kali365 has gathered browser session information and allows affiliate threat actors to replay stolen browser sessions within their own environment.

T1204.001
Malicious Link

Kali365 has directed victims to actor-controlled phishing pages through malicious links, initiating device code authorization flows or adversary-in-the-middle session capture.

T1204.004
Malicious Copy and Paste

Kali365 has dynamically generated legitimate device codes that displays on the victims screen alongside instructions to copy and paste the device code to initiate and complete a successful authentication process.

T1528
Steal Application Access Token

Kali365 has obtained OAuth access and refresh tokens by deceiving victims into completing actor-initiated device authorization requests, and intercepting authentication sessions with legitimate identity providers through adversary-in-the-middle reverse proxy infrastructure.

T1539
Steal Web Session Cookie

Kali365 has captured session cookies and related session artifacts when the interacted phishing lure acts as proxy for legitimate requests with login services.

T1550.001
Application Access Token

Kali365 has utilized an Exchange Admin module that captured admin tokens to create rogue mailbox connectors and change mail-flow rules.

T1552.001
Credentials In Files

Kali365 has searched compromised mailboxes for credential material such as seed phrases and API keys.

T1557
Adversary-in-the-Middle

Kali365 has created obfuscated phishing landing pages that act as an adversary in the middle infrastructure that intercepts communications between the victim host and legitimate services to steal credentials and user sessions.

T1564.008
Email Hiding Rules

Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them.

T1566.001
Spearphishing Attachment

Kali365 has delivered phishing emails with malicious PDF, Word, Excel, and PowerPoint attachments that direct victims to actor-controlled landing pages.

View all 17 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Artic Wolf Kali365 Device Code OAuth June 2026 Open source
    Artic Wolf Labs. (2026, June 2). Retrieved July 30, 2026.
  2. Artic Wolf Labs Kali365 Device Code April 2026 Open source
    Artic Wolf Labs. (2026, April 24). Token Bingo: Don’t Let Your Code be the Winner. Retrieved July 30, 2026.
  3. FBI IC3 Alert I-052126 Kali365 May 2026 Open source
    Federal Bureau of Investigation. (2026, May 21). Alert Number: I-052126-PSA: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens. Retrieved July 30, 2026.
  4. Huntress Kali365 Device Code June 2026 Open source
    Tanner Flip. (2026, June 11). Hook, Line, and Token: Anatomy of the Kali365 / Octopi365 Phishing-as-a-Service Kit. Retrieved July 30, 2026.
  5. SpyCloud Kali365 June 2026 Open source
    Trevor Hilligoss. (2026, June 11). Kali365: Anatomy of a Microsoft 365 Phishing-as-a-Service Kit – From Telegram Hype to FBI Takedown Theater. Retrieved July 30, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.